Solved

how do I log inbound traffic with a cisco 1721

Posted on 2004-10-13
4
994 Views
Last Modified: 2012-05-05
We are getting an unusual amount of inbound traffic for about 7 hours per night and we would like to monitor where this traffic is coming from.  Is there a way to enable the 1721 to log the inbound traffic?
0
Comment
Question by:genekurtz
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 500 total points
ID: 12298115
You can enable netflow on the interfaces

interface serial 0/0
  ip route-cache flow

interface fast 0/0
  ip route-cache flow

Examining the flows will show you source/destination IP addresses and ports.
Exporting the flow to something like NTOP will give you a tremendous amount of information:
http://www.ntop.org

Or you can enable ip accounting on the serial interface. This will also give you a lot of information with "show ip account"
0
 
LVL 1

Expert Comment

by:whippy_bb
ID: 12304648
you can also set an access control list on the external interface:

router#
router#conf t
router(config)#access 100 permit tcp any any log
router(config)#access 100 permit udp any any log
router(config)#access 100 permit ip any any log
router(config)#int s0/0
router(config-int)#ip access group 100 in
router(config-int)#exit
router(config)#logging buffered
router(config)#buffer 4096
router(config)#exit
router#wr mem

you could then log back in and type "show log" to see the reslts.
If you really wanted to get special with it you could even restrict the time the access ist was active. Check Cisco's site for more in depth details.
Regards

Whippy



0
 
LVL 5

Expert Comment

by:AutoSponge
ID: 12328499
It's unclear from your statement if the data is also hitting the LAN or if the router is unable to route the traffic and is therefore dropping it.  If you're not sure either, try:

config t
int (LAN)
ip accounting output-packets

then perform a 'show ip accounting' before and after the window.  You'll be able to see if the traffic is being requested or sent to one of your LAN devices.  If not, the router is dropping it and you'll need something else... like a firewall would really help.
0
 
LVL 5

Expert Comment

by:AutoSponge
ID: 12328501
I just realized this was for a 1721 (I was thinking 2500).  Sorry for the FW comment.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
route-map permit with a number 1 63
Home wifi - Does it matter what router? 9 89
Simultaneous work of Wi-Fi and LAN on Win10 laptop 4 83
Configure BGP 22 54
This article is a guide to configure bridging on Cisco Routers.  This is something I never knew was possible until after making a few phone calls to Cisco.  Using bridging saved our company money by not requiring us to purchase a new switch.  Bridgi…
There are two basic ways to configure a static route for Cisco IOS devices. I've written this article to highlight a case study comparing the configuration of a static route using the next-hop IP and the configuration of a static route using an outg…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

739 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question